A coordinated strike by CrowdStrike, the DOJ, the FBI, and European law enforcement has dismantled a peer-to-peer botnet that spent nearly a decade silently stealing cryptocurrency from thousands of compromised devices. The operation, which began on August 31 and was formally announced on September 1, targeted the Sality botnet and its crypto-focused payload known as EggJagger.

The malware’s trick was deceptively simple: it monitored victims’ clipboards for copied wallet addresses and swapped them with addresses controlled by the attackers. You’d copy your friend’s Bitcoin address, paste it into your wallet app, and unknowingly send funds straight to a criminal. The operator behind the scheme, tracked under the name SALTY SPIDER and assessed to be based in Russia, managed to siphon at least 12.1 million rubles (roughly $150K) through this method alone.

Two decades of infection, eight years of crypto theft

Sality has been lurking since 2003, making it ancient by malware standards. Over its lifetime, it infected more than 15,000 devices and was used for the full buffet of cybercrime: spam campaigns, distributed denial-of-service attacks, and eventually cryptocurrency theft.

The pivot to crypto came about eight years ago, when the EggJagger payload was deployed across the botnet’s infrastructure.